<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 12:25:18 +0000</lastBuildDate>
    <item>
      <title>BELL-CVE-2026-89544</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-89544</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: linux-lts, Alpaquita:25: linux-lts, Alpaquita:stream: linux-lts&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-89544</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1253 — De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Certaines d'entre elles permettent à un…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1253</link>
      <description>certfr-2026-avi-1253</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1253</guid>
    </item>
    <item>
      <title>EUVD-2026-372832</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-372832</link>
      <description>EUVD-2026-372832</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-372832</guid>
    </item>
    <item>
      <title>fkie_cve-2026-89544</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-89544</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;SUNRPC: fix gssx_dec_option_array error path bugs&lt;/p&gt;
&lt;p&gt;Four coupled defects in the gssx XDR option-array decoder make the
error paths unsafe: a NULL deref in the caller, a refcount leak on
the decoded group_info, and a latent use-after-free that the leak
fix would otherwise expose.&lt;/p&gt;
&lt;p&gt;gssx_dec_option_array() sets oa-&amp;gt;count = 1 before allocating
oa-&amp;gt;data.  If that allocation fails, -ENOMEM is returned with
oa-&amp;gt;count == 1 and oa-&amp;gt;data == NULL.  All other error paths jump
to free_oa: which frees oa-&amp;gt;data and NULLs it but also leaves
oa-&amp;gt;count == 1.  The caller trusts the count:&lt;/p&gt;
&lt;p&gt;gssp_accept_sec_context_upcall()
      gssx_dec_accept_sec_context()
        gssx_dec_option_array()        /* fails, count=1 data=NULL */
      data = res.options.data[0].value /* NULL deref */&lt;/p&gt;
&lt;p&gt;Independently, free_creds: releases the partially decoded svc_cred
with a bare kfree(creds).  gssx_dec_linux_creds() installs a
groups_alloc() result into creds-&amp;gt;cr_group_info; that object is
kvmalloc-backed and refcounted, and only put_group_info() reaches
kvfree().  A plain kfree(creds) drops the wrapper and leaks the
group_info allocation.&lt;/p&gt;
&lt;p&gt;The natural fix for the leak is to call free_svc_cred(creds) before
kfree(creds), but free_svc_cred() invokes put_group_info() on
creds-&amp;gt;cr_group_info unconditionally when non-NULL.  The existing
out_free_groups: path in gssx_dec_linux_creds() already called
groups_free() on that pointer without clearing i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;SUNRPC: fix gssx_dec_option_array error path bugs&lt;/p&gt;
&lt;p&gt;Four coupled defects in the gssx XDR option-array decoder make the
error paths unsafe: a NULL deref in the caller, a refcount leak on
the decoded group_info, and a latent use-after-free that the leak
fix would otherwise expose.&lt;/p&gt;
&lt;p&gt;gssx_dec_option_array() sets oa-&amp;gt;count = 1 before allocating
oa-&amp;gt;data.  If that allocation fails, -ENOMEM is returned with
oa-&amp;gt;count == 1 and oa-&amp;gt;data == NULL.  All other error paths jump
to free_oa: which frees oa-&amp;gt;data and NULLs it but also leaves
oa-&amp;gt;count == 1.  The caller trusts the count:&lt;/p&gt;
&lt;p&gt;gssp_accept_sec_context_upcall()
      gssx_dec_accept_sec_context()
        gssx_dec_option_array()        /* fails, count=1 data=NULL */
      data = res.options.data[0].value /* NULL deref */&lt;/p&gt;
&lt;p&gt;Independently, free_creds: releases the partially decoded svc_cred
with a bare kfree(creds).  gssx_dec_linux_creds() installs a
groups_alloc() result into creds-&amp;gt;cr_group_info; that object is
kvmalloc-backed and refcounted, and only put_group_info() reaches
kvfree().  A plain kfree(creds) drops the wrapper and leaks the
group_info allocation.&lt;/p&gt;
&lt;p&gt;The natural fix for the leak is to call free_svc_cred(creds) before
kfree(creds), but free_svc_cred() invokes put_group_info() on
creds-&amp;gt;cr_group_info unconditionally when non-NULL.  The existing
out_free_groups: path in gssx_dec_linux_creds() already called
groups_free() on that pointer without clearing i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-89544</guid>
    </item>
    <item>
      <title>GHSA-xwc4-2qqp-pxh3</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-xwc4-2qqp-pxh3</link>
      <description>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;SUNRPC: fix gssx_dec_option_array error path bugs&lt;/p&gt;
&lt;p&gt;Four coupled defects in the gssx XDR option-array decoder make the
error paths unsafe: a NULL deref in the caller, a refcount leak on
the decoded group_info, and a latent use-after-free that the leak
fix would otherwise expose.&lt;/p&gt;
&lt;p&gt;gssx_dec_option_array() sets oa-&amp;gt;count = 1 before allocating
oa-&amp;gt;data.  If that allocation fails, -ENOMEM is returned with
oa-&amp;gt;count == 1 and oa-&amp;gt;data == NULL.  All other error paths jump
to free_oa: which frees oa-&amp;gt;data and NULLs it but also leaves
oa-&amp;gt;count == 1.  The caller trusts the count:&lt;/p&gt;
&lt;p&gt;gssp_accept_sec_context_upcall()
      gssx_dec_accept_sec_context()
        gssx_dec_option_array()        /* fails, count=1 data=NULL */
      data = res.options.data[0].value /* NULL deref */&lt;/p&gt;
&lt;p&gt;Independently, free_creds: releases the partially decoded svc_cred
with a bare kfree(creds).  gssx_dec_linux_creds() installs a
groups_alloc() result into creds-&amp;gt;cr_group_info; that object is
kvmalloc-backed and refcounted, and only put_group_info() reaches
kvfree().  A plain kfree(creds) drops the wrapper and leaks the
group_info allocation.&lt;/p&gt;
&lt;p&gt;The natural fix for the leak is to call free_svc_cred(creds) before
kfree(creds), but free_svc_cred() invokes put_group_info() on
creds-&amp;gt;cr_group_info unconditionally when non-NULL.  The existing
out_free_groups: path in gssx_dec_linux_creds() already called
groups_free() on that pointer without clearing i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved:&lt;/p&gt;
&lt;p&gt;SUNRPC: fix gssx_dec_option_array error path bugs&lt;/p&gt;
&lt;p&gt;Four coupled defects in the gssx XDR option-array decoder make the
error paths unsafe: a NULL deref in the caller, a refcount leak on
the decoded group_info, and a latent use-after-free that the leak
fix would otherwise expose.&lt;/p&gt;
&lt;p&gt;gssx_dec_option_array() sets oa-&amp;gt;count = 1 before allocating
oa-&amp;gt;data.  If that allocation fails, -ENOMEM is returned with
oa-&amp;gt;count == 1 and oa-&amp;gt;data == NULL.  All other error paths jump
to free_oa: which frees oa-&amp;gt;data and NULLs it but also leaves
oa-&amp;gt;count == 1.  The caller trusts the count:&lt;/p&gt;
&lt;p&gt;gssp_accept_sec_context_upcall()
      gssx_dec_accept_sec_context()
        gssx_dec_option_array()        /* fails, count=1 data=NULL */
      data = res.options.data[0].value /* NULL deref */&lt;/p&gt;
&lt;p&gt;Independently, free_creds: releases the partially decoded svc_cred
with a bare kfree(creds).  gssx_dec_linux_creds() installs a
groups_alloc() result into creds-&amp;gt;cr_group_info; that object is
kvmalloc-backed and refcounted, and only put_group_info() reaches
kvfree().  A plain kfree(creds) drops the wrapper and leaks the
group_info allocation.&lt;/p&gt;
&lt;p&gt;The natural fix for the leak is to call free_svc_cred(creds) before
kfree(creds), but free_svc_cred() invokes put_group_info() on
creds-&amp;gt;cr_group_info unconditionally when non-NULL.  The existing
out_free_groups: path in gssx_dec_linux_creds() already called
groups_free() on that pointer without clearing i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-xwc4-2qqp-pxh3</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-89544 — SUNRPC: fix gssx_dec_option_array error path bugs</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-89544</link>
      <description>msrc_CVE-2026-89544</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-89544</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11880-1 — kernel-devel-7.2.7-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11880-1</link>
      <description>&lt;p&gt;kernel-devel-7.2.7-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;kernel-devel-7.2.7-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11880-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-89544</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-89544</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 233 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix gssx_dec_option_array error path bugs Four coupled defects in the gssx XDR option-array decoder make the error paths unsafe: a NULL deref in the caller, a refcount leak on the decoded group_info, and a latent use-after-free that the leak fix would otherwise expose. gssx_dec_option_array() sets oa-&amp;gt;count = 1 before allocating oa-&amp;gt;data.  If that allocation fails, -ENOMEM is returned with oa-&amp;gt;count == 1 and oa-&amp;gt;data == NULL.  All other error paths jump to free_oa: which frees oa-&amp;gt;data and NULLs it but also leaves oa-&amp;gt;count == 1.  The caller trusts the count:     gssp_accept_sec_context_upcall()       gssx_dec_accept_sec_context()         gssx_dec_option_array()        /* fails, count=1 data=NULL */       data = res.options.data[0].value /* NULL deref */ Independently, free_creds: releases the partially decoded svc_cred with a bare kfree(creds).  gssx_dec_linux_creds() installs a groups_alloc() result into creds-&amp;gt;cr_group_info; that object is kvmalloc-backed and refcounted, and only put_group_info() reaches kvfree().  A plain kfree(creds) drops the wrapper and leaks the group_info allocation. The natural fix for the leak is to call free_svc_cred(creds) before kfree(creds), but free_svc_cred() invokes put_group_info() on creds-&amp;gt;cr_group_info unconditionally when non-NULL.  The existing out_free_groups: path in gssx_dec_linux_creds() already called groups_free() on that pointer without clearing it, so…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: linux-aws, Ubuntu:Pro:14.04:LTS: linux-azure, Ubuntu:Pro:14.04:LTS: linux-lts-xenial, Ubuntu:Pro:16.04:LTS: linux, Ubuntu:Pro:16.04:LTS: linux-aws, Ubuntu:Pro:16.04:LTS: linux-aws-hwe, Ubuntu:Pro:16.04:LTS: linux-azure, Ubuntu:Pro:16.04:LTS: linux-gcp, Ubuntu:Pro:16.04:LTS: linux-hwe, Ubuntu:16.04:LTS: linux-hwe-edge and 233 more&lt;/p&gt;
&lt;p&gt;In the Linux kernel, the following vulnerability has been resolved: SUNRPC: fix gssx_dec_option_array error path bugs Four coupled defects in the gssx XDR option-array decoder make the error paths unsafe: a NULL deref in the caller, a refcount leak on the decoded group_info, and a latent use-after-free that the leak fix would otherwise expose. gssx_dec_option_array() sets oa-&amp;gt;count = 1 before allocating oa-&amp;gt;data.  If that allocation fails, -ENOMEM is returned with oa-&amp;gt;count == 1 and oa-&amp;gt;data == NULL.  All other error paths jump to free_oa: which frees oa-&amp;gt;data and NULLs it but also leaves oa-&amp;gt;count == 1.  The caller trusts the count:     gssp_accept_sec_context_upcall()       gssx_dec_accept_sec_context()         gssx_dec_option_array()        /* fails, count=1 data=NULL */       data = res.options.data[0].value /* NULL deref */ Independently, free_creds: releases the partially decoded svc_cred with a bare kfree(creds).  gssx_dec_linux_creds() installs a groups_alloc() result into creds-&amp;gt;cr_group_info; that object is kvmalloc-backed and refcounted, and only put_group_info() reaches kvfree().  A plain kfree(creds) drops the wrapper and leaks the group_info allocation. The natural fix for the leak is to call free_svc_cred(creds) before kfree(creds), but free_svc_cred() invokes put_group_info() on creds-&amp;gt;cr_group_info unconditionally when non-NULL.  The existing out_free_groups: path in gssx_dec_linux_creds() already called groups_free() on that pointer without clearing it, so…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-89544</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3321 — Linux Kernel: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3321</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Daten oder den Systemzustand zu manipulieren, Denial-of-Service-Zustände herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Daten oder den Systemzustand zu manipulieren, Denial-of-Service-Zustände herbeizuführen oder andere, nicht näher spezifizierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3321</guid>
    </item>
  </channel>
</rss>
